Executive brief
A critical vulnerability exists in the Oracle Universal Work Queue, a component of the Oracle E-Business Suite used for managing and distributing tasks across an organization. A low-privileged user can exploit this flaw over the network to take full control of the system. This could lead to the exposure of sensitive business data, disruption of operations, and potential unauthorized access to other connected Oracle products.
Technical details
This vulnerability is located in the Work Provider Site Level Administration component of Oracle Universal Work Queue (Oracle E-Business Suite). It is classified as an improper access control or privilege management issue (CWE-284, CWE-269). An attacker with low-level user privileges can exploit this flaw via HTTP over the network without any user interaction. The vulnerability carries a high CVSS score due to a 'scope change,' meaning a successful exploit can impact other components or products beyond the Universal Work Queue itself. Successful exploitation results in a complete loss of confidentiality, integrity, and availability. Affected versions range from 12.2.3 through 12.2.15.
Affected products
- Oracle Universal Work Queue 12.2.3-12.2.15
Timeline
- 2026-06-17: disclosed
- 2026-06-17: advisory